Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Go ReviewGo code review for correctness, security, performance, and best practices. Use for manual review of Go code checking design decisions and patterns requiring human judgment. For detailed category-specific checks, see reference/. Use when this capability is needed.
-
tomevault-io Bundle AuditUse this skill when the user asks for a codebase audit or code review. Parallel agents find bugs, architectural rot, dead weight, and security holes.
-
tomevault-io Bundle Code CommentsExtract comment locations from code files for analysis. Use when cleaning comments, auditing code documentation, or analyzing comment patterns. Supports Python, JavaScript, TypeScript, Go, Rust, Java, C/C++, Ruby, PHP, Shell scripts. Trigger terms - comments, extract comments, code comments, comment analysis, documentation audit, comment cleanup. Use when this capability is needed.
-
tomevault-io Bundle Git ExpertGit expert with deep knowledge of merge conflicts, branching strategies, repository recovery, performance optimization, and security patterns. Use PROACTIVELY for any Git workflow issues including complex merge conflicts, history rewriting, collaboration patterns, and repository management. If a specialized expert is a better fit, I will recommend switching and stop. Use when this capability is needed.
-
tomevault-io Bundle Find BugsFind bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch. Use when this capability is needed.
-
tomevault-io Bundle Test TaggingAnalyzes test suites in any language and tags each test with a standardized set of traits (positive, negative, critical-path, boundary, smoke, regression, integration, performance, security). Use when the user wants to categorize, audit, or label tests with traits. Works with .NET (MSTest TestCategory / xUnit Trait / NUnit Category / TUnit Property), Python (pytest markers; unittest has no canonical tag syntax so report-only), TypeScript/JavaScript (Jest/Vitest test names, describe-block conventions), Java (JUnit 5 @Tag / TestNG groups), Go (subtest naming / build tags / file _test.go), Ruby (RSpec metadata), Rust (cargo test naming / cfg attributes), Swift (XCTest test plans / Swift Testing @Tag), Kotlin (JUnit @Tag / Kotest tags), PowerShell (Pester -Tag), C++ (GoogleTest filter prefixes / Catch2 [tags] / doctest decorators). Auto-edits when the framework has canonical syntax; falls back to report-only otherwise. Do not use for writing new tests, running tests, or migrating frameworks.
-
tomevault-io Bundle Htmx Universal PatternsUse when working with the definitive guide for building Hypermedia-Driven Applications (HDA) using HTMX, prioritizing security and UX patterns.
-
tomevault-io Bundle Chrome Release VerifyEnd-to-end Chrome security backport for an Electron release branch. Given a Chrome Releases blog URL and a branch (e.g. 41-x-y), determines which CVE fixes are missing from the *actual synced source*, writes the cherry-pick patches locally, validates them with `e sync --3` + `lint --patches`, then pushes a single PR. Use when asked to backport a Chrome security release to N-x-y, "is CVE-X already in N-x-y?", or to produce/validate the cherry-pick set for a release branch. Use when this capability is needed.
-
tomevault-io Bundle Elithrar Dotfiles DotfilesDifferential Security Review
-
tomevault-io Bundle PrereviewReview unpushed commits before pushing for code quality, bugs, security issues, and error handling. Use when preparing to push commits, want pre-push code review, or need to validate changes before pushing. Runs comprehensive analysis using specialized review agents. Use when this capability is needed.
-
tomevault-io Bundle Github Cargo Dependabot ReviewReview Dependabot PRs updating Rust/Cargo crates with a security-focused crates.io tarball diff before commenting. Use when this capability is needed.
-
tomevault-io Bundle Ghost ProxyStarts and controls the reaper MITM proxy to capture, inspect, search, and replay HTTP/HTTPS traffic between clients and servers. Capabilities include starting/stopping the proxy scoped to specific domains, viewing captured request/response logs, searching traffic by method/path/status/host, and inspecting full raw HTTP entries for security analysis. Use when the user asks to "start the proxy", "capture traffic", "intercept requests", "inspect HTTP traffic", "search captured requests", or "view request/response". Use when this capability is needed.
-
tomevault-io Bundle Reverse AnalyzePerform reverse engineering analysis on code or binary for security research. Use when user says "reverse engineer", "analyze binary", "decompile", or investigating undocumented systems and legacy code. Use when this capability is needed.
-
tomevault-io Bundle Go LivePre-flight checks and deployment procedure for live trading. Use when deploying to mainnet, going live with a new asset, or transitioning from paper to live. Covers code parity audit, config validation, first-30-min monitoring, and rollback. Use when this capability is needed.
-
tomevault-io Bundle ClauditAudit and optimize Claude Code configuration with dynamic best-practice research Use when this capability is needed.
-
tomevault-io Bundle AdsMulti-platform paid advertising audit and optimization skill. Analyzes Google, Meta, YouTube, LinkedIn, TikTok, Microsoft, and Apple Search Ads. 225+ checks with scoring, parallel agents, industry templates, and AI creative generation. Use when this capability is needed.
-
tomevault-io Skill Audit CodeSecurity-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities Use when this capability is needed.
-
tomevault-io Bundle Sdlc ReviewUse when reviewing code, verifying implementations, checking security, validating acceptance criteria, or conducting code reviews for a completed implementation.
-
tomevault-io Bundle Translation Release AuditAudit FeedFlow localization, store listing, live App Store/Play Store listing state, and screenshot-copy changes. Use when checking whether new app translations were added or completed, whether store copy/localized listings changed, whether live store metadata is stale, or whether screenshots need to be regenerated or uploaded. Use when this capability is needed.
-
tomevault-io Bundle Rube De Cc Skills SecurityDLC: Security Scan
-
tomevault-io Bundle Source AuditMulti-language source code security audit. Use when analyzing source code for vulnerabilities. Supports Python, JavaScript, Go, Rust, Java, C/C++. Use when this capability is needed.
-
tomevault-io Bundle Ghost ReportGhost Security — combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit, or combined scan results. Use when this capability is needed.
-
tomevault-io Bundle Ghost Repo ContextScans directory structure, detects projects, maps dependencies, and documents code organization into a repo.md file. Use when the user needs a codebase overview, project structure map, or repository context before security analysis. Use when this capability is needed.
-
tomevault-io Bundle Open Source🔓 Open source governance demonstrating security excellence through transparent practices following Hack23 Open Source Policy Use when this capability is needed.
-
tomevault-io Bundle SkillsscanScan a repository to bootstrap new skills or audit and update existing ones Use when this capability is needed.
-
tomevault-io Bundle ModernizingGo code modernization guide covering Go 1.20-1.26 new features. Use when writing, reviewing, or refactoring Go code to adopt modern idioms — generics, iterators, error handling, concurrency patterns, stdlib collections, HTTP routing, testing, security APIs, and tooling. Use when this capability is needed.
-
tomevault-io Bundle Paper Reviewer Results To ClaimsAudit whether paper claims are fully supported by the supplied evidence. Use when this capability is needed.
-
tomevault-io Bundle Skill InstallInstall Claude skills from GitHub repositories with automated security scanning. Triggers when users want to install skills from a GitHub URL, need to browse available skills in a repository, or want to safely add new skills to their Claude environment. Use when this capability is needed.
-
tomevault-io Bundle Security CheckComprehensive AI-powered security scanning suite with 48 skills covering OWASP Top 10, 7 language-specific deep scanners (Go, TypeScript, Python, PHP, Rust, Java, C#), supply chain analysis, infrastructure-as-code scanning, and 3000+ checklist items. Use when you need to run a security audit, find vulnerabilities, scan a PR for security issues, or perform a penetration test on a codebase. Use when this capability is needed.
-
tomevault-io Bundle Auditor QuizGenerate and administer interactive knowledge quizzes for security auditors based on repository documentation and code. Use when an auditor needs to be tested on their understanding of a codebase, protocol mechanics, security considerations, potential vulnerabilities, or core functionality. Triggers include requests like "quiz me on", "test my knowledge", "generate a quiz", or when preparing for security audits and code reviews. Use when this capability is needed.
-
tomevault-io Bundle AnalysisAnalyze feature requirements, dependencies, and security considerations. Use when this capability is needed.
-
tomevault-io Bundle Spring SecurityAuthentication, authorization, JWT, OAuth2, CSRF, CORS, and security filter chain. Use when this capability is needed.
-
tomevault-io Bundle Review DepsAudit project dependencies for vulnerabilities, license compliance risks, and staleness. Runs native audit tools (npm audit, pip audit, cargo audit, etc.), queries Dependabot alerts, and dispatches parallel agents for CVE analysis, license risk, and upgrade complexity. This skill should be used when users want to review dependencies, check for vulnerable packages, audit licenses, plan upgrades, or assess supply chain risk. Use when this capability is needed.
-
tomevault-io Bundle Magic SkillUse this skill when asked about the magic skill code or secret skill phrase
-
tomevault-io Bundle Ngerakines Jd Jd Jdex AuditJohnny.Decimal JDex Audit
-
tomevault-io Bundle Ohdearquant Lionagi LionagiSecurity review procedure
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include go-review, audit, code-comments. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.